19 Sep
|
Gradientflo Labs
|
Hyderabad
19 Sep
Gradientflo Labs
Hyderabad
Role Overview
You will be the guardian of trust at Vibecoderz. Developers will only commit their code, data, and learning journeys into a platform they know is secure, private, and compliant. You’ll build Vibecoderz’ end-to-end security posture, ensure compliance with global frameworks (SOC 2, GDPR, ISO 27001), and proactively defend against threats like prompt injection, data poisoning, and model misuse.
This is not just about firewalls and audits. This is about making security invisible but unbreakable — so users feel flow, while knowing their data and code are safe.
Key Responsibilities
1. Security Architecture
- Define and enforce Vibecoderz’ security-first architecture across all layers (frontend, backend, AI, infra).
- Design secure patterns for AI agent communication (A2A via Pub/Sub) to prevent leakage or injection attacks.
- Compliance & Certifications
- Lead Vibecoderz through SOC 2 Type II, GDPR, ISO 27001, HIPAA (where relevant).
- Own documentation, audits, and compliance playbooks.
- Application Security
- Implement secure coding standards, static/dynamic analysis pipelines, and dependency scanning.
- Run regular penetration testing and bug bounty programs.
- Cloud & Infrastructure Security
- Secure GCP stack (Cloud Run, Firestore, Pub/Sub, Cloud Tasks, Workflows).
- Manage IAM policies, VPC service controls, and secrets management.
- AI/LLM Security
- Develop guardrails for LLMs against prompt injection, malicious payloads, or unsafe content.
- Build continuous AI evals for hallucination, bias, and red-team attacks.
- Data Privacy & Governance
- Ensure secure handling of developer data, GitHub integrations, and learning graphs.
- Define data retention, anonymization, and encryption-at-rest/in-transit policies.
- Monitoring & Incident Response
- Build a Security Operations Center (SOC) playbook.
- Implement observability pipelines (OpenTelemetry + GCP Trace) for security events.
- Own incident response, from detection → containment → resolution.
- Cross-Functional Leadership
- Partner with CTO/DevOps to embed security into CI/CD.
- Partner with CPO/PM to balance UX speed with security tradeoffs.
- Mentor engineers on “security-as-craft” culture.
Success Metrics
90 Days (Probation):
- Establish secure CI/CD pipelines with SAST/DAST checks.
- Define and document Vibecoderz’ security baseline (policies, access, data handling).
- Run the first red-team simulation against TutorAgent + artifacts.
12 Months:
- Achieve SOC 2 Type II certification.
- Maintain zero P1/P2 security breaches.
- Achieve 99.99% uptime without security-related downtime.
- Establish a continuous security monitoring dashboard visible to leadership.
Must-Haves
- 10+ years in security engineering or compliance leadership in SaaS or developer platforms.
- Proven success in achieving SOC 2 / ISO 27001 / GDPR compliance.
- Solid background in cloud-native security (GCP preferred).
- Expertise in application security, IAM, VPC, encryption, and key management.
- Experience designing security frameworks for AI/LLM products.
Nice-to-Haves
- Prior experience in developer-first SaaS.
- Contributions to security open-source projects or standards.
- Experience with federated identity, SSO, and enterprise compliance.
- Background in offensive security / red-team practices.
Tech Stack Visibility
- Infra & Cloud: GCP (Cloud Run, Firestore, Pub/Sub, Cloud Tasks, Workflows)
- CI/CD Security: GitHub Actions, Snyk, Dependabot
- Observability & Monitoring: OpenTelemetry, GCP Trace, SIEM tools
- AI Security: LangSmith/Langfuse evals, custom LLM guardrails
- Compliance: SOC 2, ISO 27001, GDPR frameworks
- Identity & Access: Firebase Auth, IAM, VPC Service Controls
- Encryption: KMS, TLS 1.3, AES-256
Assessment
Objective: Validate ability to design secure architecture + compliance strategy for Vibecoderz.
Assessment (3-Part):
1. Security Design (Written)
- Draft a security architecture doc for Vibecoderz’ core flow: Text → Course → Artifact → Mini-App.
- Must include:
- Data encryption flow (at rest + in transit).
- Access control model (OAuth + Firebase Auth).
- AI guardrails (prompt injection, unsafe outputs).
- Threat modeling for Firestore + Pub/Sub.
- Compliance Playbook
- Outline a 12-month plan to achieve SOC 2 Type II certification.
- List top 5 risks for Vibecoderz’ compliance and your mitigation plan.
- Coding Assessment
- Implement a secure FastAPI microservice with:
- OAuth2 authentication.
- Rate limiting (per-user).
- Secure logging (PII masked).
- Deploy to Cloud Run with IAM policies.
- Deliver a Postman collection with working requests.
Deliverables:
- Written security design doc (3–4 pages).
- Compliance roadmap (slide deck or doc).
- GitHub repo with code + deployment instructions.
📌 Head of Security & Compliance (Hyderabad)
🏢 Gradientflo Labs
📍 Hyderabad